Networking
Security
Telco/ISP
Storage
Hardware
Software
Oddware
Strategy
Finance
Training & Development
Login
|
Sign up for our daily tech newsletter
|
Sitemap
Reviews
|
Galleries
|
Events
|
Net Seminars
|
Whitepapers
|
Downloads
|
Newsletter
|
Videos
|
Topics
Home
>
News
>
Technology
>
Security
>
Poor HR leaves firms open to security risks
Security
Poor HR leaves firms open to security risks
By
Robert Jaques
Mar 9, 2007 8:24 AM
Tags:
poor
|
hr
|
leaves
|
firms
|
open
|
security
|
risks
'Employee education gap' putting employers and employees in danger.
Small UK businesses are leaving themselves vulnerable to unnecessary IT security risks because of poor human resources practices, it was claimed today.
A poll of over 1,000 SMEs (50-250 employees) across Europe conducted by
McAfee
found that only 32 percent have IT security as an aspect of employee induction.
The research indicated that the UK leads the induction drive, and that British businesses are the most likely to hold induction sessions for all employees.
However, more than a third of businesses in France and Italy do not have inductions for all employees.
Some 70 percent of respondents believe that employers are more sensitive to the risks associated with new employees than they were three years ago.
However, only 39 percent of businesses have guidelines for employees on email content/language, 28 percent for the use of portable storage devices and 23 percent for laptop use.
In the majority of cases where security issues are raised, most businesses feel that the end user is more culpable than the employer, highlighting serious implications for employee and employer liability.
For example, 55 percent felt that an employee should be held responsible for a personal email that spreads a virus on the company network.
Similarly a stolen laptop is also seen as the responsibility of the employee by 67 percent of respondents.
The research warned that current approaches may be "misguided" in terms of culpability for security breaches.
Although employee actions may result in security breaches, the employer is often ultimately responsible for the processes and conditions that surround security incidents.
Greg Day, security analyst at McAfee, said: "While many businesses make a priority of employee induction, many are failing effectively to cover a major part of any employees working life: their PC and internet usage policies.
"Companies are failing to capture the opportunity presented by new starters to instil a sense of vigilance and security into the workforce.
"This oversight, coupled with a clear lack of enforcement, increases the risk of new employees consciously or inadvertently breaching corporate security protocols."
Typically, inductions are shortest in Germany where 36 percent of businesses complete full HR inductions in fewer than three hours.
At the other end of the spectrum, Spanish inductions are most likely to take more than two days (32 percent of respondents), while UK and French businesses strike a balance at half a day.
Billy Hamilton Stent, a director at consultancy
LoudHouse Research
which undertook the study, said: "The induction process provides an ideal opportunity to engender a vigilant response to information security for end users.
"It is not a case of issuing a list of dos and don'ts, but more a process of establishing trust, security and clear working procedures that reduce employee and employer risk. It is unfortunate that only a minority of businesses see it in this way."
Copyright ©v3.co.uk
Related Articles
Black Hat founder: SSL is broken
Verizon boosts Australian data-breach team
Chatroulette collecting IP addresses, screenshots
Bottle Domains termination stands: auDA
Breaking Stories
iiNet pays $60m for AAPT consumer business
NBN coverage maps reveal 93 percent fibre footprint
iPhones missing at NZ midnight launch
ACMA approves in-flight mobile use
US Government sues Oracle
Email this
Print this
Tweet this
Send us your tips
Comments
Be the first to comment on this article.
Thoughts on this article? Add a comment below.
Comment:
Want to participate in the discussion?
Register for FREE
Or
log in
now to comment
Ads by Google
IT Whitepapers
Top Categories
Networking
Software Development
IT Management
Enterprise Applications
Storage
more technology whitepapers »
Latest Technology Jobs
Change and Configuration Manager
Test Architect/Database Development - CBD Location up to $95/hour
C++ Software Engineer - Trading Systems
Network Engineers
Senior C++ Software Engineer - Investment Banking/Trading Systems
Oracle eBusiness Services Delivery Manager
more technology jobs »
Top Stories
Oracle shuts down open source test servers
Playing nice with the open source community, Larry?
Google hosts election debate
Lundy, Fletcher and Ludlam face off on tech policies.
Telstra fined $18.5m for exchange access
Kept competitive DSLAM kit out.
Chatroulette collecting IP addresses, screenshots
Oracle shuts down open source test servers
Telstra launches 200GB ADSL assault
Google fibre method "could save NBN $10 billion"
ISPs rally against Telstra ADSL price cuts
NBN key to Greens’ Labor support
Torrent community goes to town on ICSL study
ISPs rally against Telstra ADSL price cuts
iPad owners a 'selfish elite'
Australia scores a C on Akamai broadband report card
Latest Videos
See all videos »
Latest Comments
"anyone who knows ANYTHING about RF knows how idiotic it is to have a "bare" antennae that will ..."
on
iPhone 4 worst affected by 'death grip'
by
Res
Jul 31, 2010 10:00 AM
"Now Julia, if only you would promise not to filter the internet in your next term of government ..."
on
NBN coverage maps reveal 93 percent fibre footprint
by
hsvandrew
Jul 31, 2010 9:33 AM
"@Nate - my fears are that if we use a national consortium as an interface to international ..."
on
Analysis: Is Victoria stealing New South Wales' ICT crown?
by
heavenlyhaloes
Jul 31, 2010 12:41 AM
"Did anybody notice that on Apple's website the iPhone is missing the AT&T logo on the top bar? ..."
on
iPhones missing at NZ midnight launch
by
brownenicola
Jul 30, 2010 10:18 PM
"@digger11 - when will you learn just to remain quiet when you don't have all the facts or a ..."
on
Comment: iiTrial is a little bit of history repeating
by
Bazwalt
Jul 30, 2010 7:13 PM
Polls
Did Google breach the Telecommunications Interception or Privacy Acts during its WiFi wardrive?
Yes. There is no excuse for collecting this data.
No. If your wireless network is unsecured, you have no right to complain
|
View results
Yes. There is no excuse for collecting this data.
28%
No. If your wireless network is unsecured, you have no right to complain
72%
TOTAL VOTES: 1873
Vote
view previous polls »